OC Me
The bitcoin-backed online identity that pays you to use it. me.ochk.io is the consumer surface of OrangeCheck. End-users sign up once with email-OTP (default · no wallet required), with a Bitcoin wallet via BIP-322, or with an existing OC identity from a sibling site, and earn sats automatically as integrating sites bill the canonical billable-event taxonomy (sessions, payments, state transitions). BIP-322 users hold their own signing key from day one; email-OTP users hold no key here. Both paths sign in in-place on me.ochk.io — no redirect to a separate auth host.
Custody, stated plainly. Sign-in self-custody is live and real. Earned sats
are not: there is no stored balance — it is recomputed from signed envelopes on
every read — and the party who owes it is OrangeCheck. That is deliberate and
temporary. OrangeCheck operates every role during bring-up, including custodian,
because that is how the system gets proved before anyone else will take one.
Federation custody plus self-custody graduation is the destination; the live
state is published at me.ochk.io/custody and
machine-readable at /api/federations.
The protocol surface is the same OC Attest + OC Lock + OC Stamp + OC Agent primitives documented elsewhere in these docs. me.ochk.io is the commercial layer on top: same envelopes, same canonical messages, same offline verification — packaged as a hosted product so consumers and integrators get a working stack without standing up their own federation.
What me.ochk.io is, and what it isn't
| Is | A consumer identity layer. Sign in once at any integrating site; sats accrue to your identity automatically as a signed, verifiable balance. |
| Is | A drop-in OAuth peer. Integrators add the OC button alongside Google / Apple / magic-link. First-time users need no wallet and no seed phrase. |
| Is | An integrator-configurable pricing substrate. Each integrator declares per-event prices and user-share splits via IntegratorPriceConfig. OC takes a fixed 20% platform fee. |
| Is | A designed graduation path. The sweep to self-custody (bip-322) or to a fedimint federation of the user's choice preserves the oc identity, history, attest tier and connected-sites list. It is not live: no federation is bound yet, so there is nothing to sweep from. |
| Isn't | A new protocol. Every envelope me.ochk.io produces is identical to one a user could publish themselves via the canonical OC Attest / Stamp / Agent primitives. |
| Isn't | A permanent custodian. OrangeCheck holds user balances today; it is not the design. The architecture targets federation guardians collectively holding the threshold key, with OC the company as at most one guardian among several — see NON_CUSTODIAL_AUDIT.md for the current-state breakdown. |
| Isn't | A token issuer. Sats are the unit of account. No me.ochk.io token, no governance token, no airdrop. The platform fee is in sats, settled in sats, displayed in USD alongside for human readability. |
Quickstart paths
| For… | Start here |
|---|---|
| End users | Sign up at me.ochk.io/signin. Email-OTP (default, no key of your own) or BIP-322 (paste address, sign in-page). |
| Integrators (developers) | The 5-minute integrate quickstart walks install → drop-in button → configure prices → verify webhook → ship. |
| SDK reference | @orangecheck/me-client — signInWithOc, oc.session, oc.payment, oc.event, oc.webhook, oc.config, withOcAuth · paired with @orangecheck/auth-client for the React provider + useOcSession hook. |
| Protocol grounding | Attest, Lock, Stamp, Agent — the four protocol verbs me.ochk.io is built on. |
| Getting sats out | me.ochk.io/me/graduate — who holds what today, the cash-out that exists now, and the condition that opens graduation. |
Sub-pages in this section
- Quickstart — install → drop-in → configure → verify → ship
- SDK reference — every export from
@orangecheck/me-client - Integrations — OAuth-peer pattern, sample configs, webhook reception
- Webhooks — signature verification, raw-body warning, retry semantics
- API reference — every
me.ochk.io/api/*endpoint, owner-gating, rate limits - Federation custody — descriptor schema, graduation envelope, guardian rotation
Where the source of truth lives
- Protocol contracts:
oc-attest-protocol,oc-lock-protocol,oc-stamp-protocol,oc-agent-protocol. The v1.2-draft-1 federation custody extension is atoc-attest-protocol/FEDERATION-CUSTODY.md. - Web app:
oc-me-web— the me.ochk.io marketing + authenticated app surface. - SDK:
oc-packages/me-client— published to npm at@orangecheck/me-client. - Docs: this section, in
oc-docs. Cross-referenced from /sdk and /developer/docs on me.ochk.io.
The contract is the protocol; me.ochk.io is one implementation. Anyone can run their own me-equivalent against the same envelopes — that's the product strategy.